Repository navigation
Scope CI secret-scan history to what the run would land - #118
Merged
seathatflowsinourveins merged 1 commit intoSep 23, 2026
Merged
Conversation
…EAD) gitleaks' git mode scans every fetched ref by default, and the job checks out with fetch-depth 0, so one open branch's finding failed every other pull request: PR #116's branch (four generic-api-key hits on 64-hex fingerprint values, commit b801fe4) failed PR #117's required secret-scan. Scanning HEAD's ancestry covers a pull request's merge commit or main on push; each branch is still scanned by its own pull request. Records the resolution of the scope decision .gitleaks.toml and docs/github-automation.md had left to the coordinator. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Codex Review SummaryThis comment shows the latest Codex review activity on this pull request.
ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings. |
seathatflowsinourveins
deleted the
claude/secret-scan-ancestry-scope-20260923
branch
September 23, 2026 14:11
5 of 8 tasks
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Why
The
secret-scanjob runsgitleaks git .afteractions/checkoutwithfetch-depth: 0. By default gitleaks scans every fetched ref, including every other open branch.On 2026-09-23 this made PR #117's required check fail. Its secret-scan artifact
secret-scan-35870341699reported 4generic-api-keyfindings. All four are inobservability/memory-scheduled-20260923.jsonlines 132-144 at commitb801fe4, which is on PR #116's branch and is not an ancestor of #117. The flagged values are 64-hex rejection fingerprints under a"key"field. I inspected their length and charset only and did not print them; they look like false positives, but #116's owner has to review and fix them in #116.Change
--log-opts="HEAD"in thegit-mode scan. It now scans the ancestry of what the run would land: a PR's merge commit, ormainon push. Each branch is still scanned in its own PR run. The working-treedirscan is unchanged..gitleaks.toml(lines 101-108) anddocs/github-automation.mdhad left to the coordinator. Both now record the resolution.Alternative considered: keep all refs and require every open branch to be clean. Rejected, because it couples every PR's required check to unrelated branches. Overturn condition: a secret reaching
mainthat an all-refs scan would have caught but an ancestry scan did not. That can't happen for commits that land, since they are ancestors ofmain.Evidence
validate.py: passed.evidence_manifest.py --check: passed.git diff --check: clean.validatejob runs the pinned actionlint.secret-scanrun is the acceptance check for the new scope.🤖 Generated with Claude Code